CYBER ATTACK

Critical ServiceNow AI Platform Flaw Allows Remote Code Execution Attacks

Critical ServiceNow AI Platform Flaw Allows Remote Code Execution Attacks

CYBER ATTACKZerowl

A serious flaw in ServiceNow's AI Platform has been fixed, exposing businesses to the dangers of unauthenticated remote code execution (RCE) in the.

Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks

Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks

CYBER ATTACKZerowl

Claude Code Weaknesses Anthropic's Claude Code has a serious security flaw that shows how threat actors can use repository configuration files to run.

A 27-year-old Telnet vulnerability gives attackers root access.

A 27-year-old Telnet vulnerability gives attackers root access.

CYBER ATTACKZerowl

Telnet, which is 27 years old, gives attackers root access. A recently discovered flaw in the GNU telnet daemon (telnetd) A 27-year-old security.

Mozilla Releases Firefox 148 With New Sanitizer API to Block XSS Attacks

Mozilla Releases Firefox 148 With New Sanitizer API to Block XSS Attacks

CYBER ATTACKZerowl

To strengthen defenses against Cross-Site Scripting (XSS) attacks, one of the most persistent threats on the web, Firefox has released a significant.

Kali Linux Integrates Claude AI via Model Context Protocol to Enhance Offensive Security

Kali Linux Integrates Claude AI via Model Context Protocol to Enhance Offensive Security

CYBER ATTACKZerowl

Natural language-driven penetration testing is now possible with Kali Linux thanks to the Model Context Protocol's (MCP) smooth integration with.

Hacker Jailbreaks Claude AI to Write Exploit Code and Steal Government Data

Hacker Jailbreaks Claude AI to Write Exploit Code and Steal Government Data

CYBER ATTACKZerowl

Claude AI Exploited During a month-long campaign beginning in December 2025, a hacker used Anthropic's Claude AI chatbot to find vulnerabilities, create.

Critical Cisco SD-WAN 0-Day Vulnerability Exploited Since 2023 to Gain Root Access

Critical Cisco SD-WAN 0-Day Vulnerability Exploited Since 2023 to Gain Root Access

CYBER ATTACKZerowl

0-Day Vulnerability in Cisco SD-WAN Threat actors have been using a serious zero-day vulnerability in Cisco's Catalyst SD-WAN products since 2023 to get.

Cisco SD-WAN Zero-Day Under Active Exploitation Grants Attackers Root-Level Control

Cisco SD-WAN Zero-Day Under Active Exploitation Grants Attackers Root-Level Control

CYBER ATTACKZerowl

Since at least 2023, sophisticated threat actors have been actively using a critical zero-day vulnerability in Cisco's Catalyst SD-WAN Controller.

Anthropic Presents Claude Code, a Remote Terminal Control System for Mobile Devices

Anthropic Presents Claude Code, a Remote Terminal Control System for Mobile Devices

CYBER ATTACKZerowl

Discover how The "Remote Control" feature in Anthropic's most recent Claude Code update allows developers to control local terminal sessions from web.

SURXRAT Android RAT Attacking Users Gain Complete Device-Control and Data Exfiltration

SURXRAT Android RAT Attacking Users Gain Complete Device-Control and Data Exfiltration

CYBER ATTACKZerowl

Due to the growing availability of highly advanced malicious tools, the mobile threat landscape is undergoing a dramatic shift toward professionalized.

OAuth Attacks in Entra ID Can Leverage ChatGPT to Compromise User Email Accounts

OAuth Attacks in Entra ID Can Leverage ChatGPT to Compromise User Email Accounts

CYBER ATTACKZerowl

Through a tactic known as OAuth consent abuse, Microsoft Entra ID is increasingly becoming a target for threat actors who are constantly searching for new.

How SOC Analysts Can Save 28 Minutes Per Alert Review

How SOC Analysts Can Save 28 Minutes Per Alert Review

CYBER ATTACKZerowl

Review of SOC analysts' alerts When an alert proves to be harmless, how much time do you spend reviewing it This article explores investigating single.

CISA Verifies Active FileZen Vulnerability Exploitation

CISA Verifies Active FileZen Vulnerability Exploitation

CYBER ATTACKZerowl

CISA Verifies FileZen Vulnerability Exploit Threat actors are actively taking advantage of a serious flaw in FileZen by Soliton Systems K.K., according to.

SolarWinds Critical Serv-U Vulnerabilities Enables Root Access

SolarWinds Critical Serv-U Vulnerabilities Enables Root Access

CYBER ATTACKZerowl

Vulnerabilities in SolarWinds Serv-U The Serv-U file server software has received an urgent security update to address several serious flaws that could.

Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware

Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware

CYBER ATTACKZerowl

Threat actors have actively exploited a critical vulnerability in Apache ActiveMQ, resulting in the full deployment of the LockBit ransomware throughout.

SURXRAT Malware Gives Hackers Complete Access To Android Devices

SURXRAT Malware Gives Hackers Complete Access To Android Devices

CYBER ATTACKZerowl

SURXRAT is a sophisticated Android Remote Access Trojan (RAT) that is marketed via a malware-as-a-service (MaaS) business model This article explores.

SolarWinds Serv-U Critical Vulnerabilities Allow Attackers to Gain Root Access

SolarWinds Serv-U Critical Vulnerabilities Allow Attackers to Gain Root Access

CYBER ATTACKZerowl

On February 24, 2026, SolarWinds released Serv-U version 15.5.4, which fixes four serious flaws that could give hackers root access to compromised systems.

Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft

Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft

CYBER ATTACKZerowl

CPSD CryptoPro Secure Disk for BitLocker Vulnerabilities Numerous flaws have been found in the popular encryption program CryptoPro Secure Disk (CPSD) for.

Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories

Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories

CYBER ATTACKZerowl

Software developers are being actively targeted by a coordinated attack campaign using malicious repositories that pose as authentic Next.js projects and.

Microsoft to Stop Support for Windows Server 2016 and Windows 10 2016

Microsoft to Stop Support for Windows Server 2016 and Windows 10 2016

CYBER ATTACKZerowl

Microsoft Ends Support for Windows Server 2016 and Windows 10 2016 Three Windows releases that were first released in 2016 are approaching end-of-support.

Microsoft Released Updates for Windows 11, Version 25H2 and 24H2 Systems

Microsoft Released Updates for Windows 11, Version 25H2 and 24H2 Systems

CYBER ATTACKZerowl

Discover how Updates from Microsoft Windows 11 25H2 and 24H2 For Windows 11 versions 25H2 and 24H2, KB5077241, an optional non-security update, has been.

Hackers Use ChatGPT In OAuth Attacks To Breach Entra ID and Access Emails

Hackers Use ChatGPT In OAuth Attacks To Breach Entra ID and Access Emails

CYBER ATTACKZerowl

OAuth-based application attacks are becoming more common, according to Red Canary's Threat Research team This article explores risk oauth attacks. . One.

CISA Warns of Active Exploitation of FileZen Vulnerability

CISA Warns of Active Exploitation of FileZen Vulnerability

CYBER ATTACKZerowl

A serious flaw in Soliton Systems' FileZen software has been added to the U.S This article explores risks filezen secure. . Cybersecurity and.

LockBit Ransomware Is Deployed via RDP Access Using an Apache ActiveMQ Vulnerability

LockBit Ransomware Is Deployed via RDP Access Using an Apache ActiveMQ Vulnerability

CYBER ATTACKZerowl

Threat actors recently gained initial access to an organization's network by taking advantage of a vulnerability (CVE-2023-46604) in an Apache ActiveMQ.

ZeroDayRAT Malware Targets Android and iOS, Stealing Sensitive Data From Millions

ZeroDayRAT Malware Targets Android and iOS, Stealing Sensitive Data From Millions

CYBER ATTACKZerowl

Discover how The landscape of malware-as-a-service (MaaS) keeps pushing the limits of cybercrime. Researchers at Cyberthint have examined a new mobile.

U.S. Slaps Sanctions on Exploit Brokers Linked to Theft of Government Hacking Tools

U.S. Slaps Sanctions on Exploit Brokers Linked to Theft of Government Hacking Tools

CYBER ATTACKZerowl

A shadowy network of exploit brokers trafficking stolen U.S. government cyber tools has been the target of a significant crackdown by the US Department of.

Top 5 this week

Page 20 of 44